
Critical WordPress SAML SSO Flaws Enable Unauthenticated Admin Account Takeover
Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On WordPress plugin could allow unauthenticated attackers to forge SAML assertions and access /wp-admin as any existing account, including administrators. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have reportedly been targeted by opportunistic scanning activity. DigitalOcean’s security team detected […]
The post Critical WordPress SAML SSO Flaws Enable Unauthenticated Admin Account Takeover appeared first on Cyber Security News.